Exploitation Summary
EIP tracks 2 public exploits for CVE-2012-5691.
PoCs published by Metasploit, including Metasploit module exploits/windows/fileformat/real_player_url_property_bof.
AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in RealPlayer <=15.0.6.14 via a malicious .rm file. It leverages the insecure usage of GetPrivateProfileString to trigger the vulnerability, achieving remote code execution.
Description
Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted RealMedia file.
Exploits (2)
This Metasploit module exploits a stack-based buffer overflow in RealPlayer <=15.0.6.14 via a malicious .rm file. It leverages the insecure usage of GetPrivateProfileString to trigger the vulnerability, achieving remote code execution.
This Metasploit module exploits a stack-based buffer overflow in RealPlayer <=15.0.6.14 via a malicious .rm file, leveraging insecure handling of the URL property in InternetShortcut sections. It uses SEH overwrites and a short jump to trigger payload execution.